package SV_XSS_COOKIE_SECURE;

public class Vulnerable_02 {
    String sessionID = generateSessionId();
    Cookie c = new Cookie("session_id", sessionID);
   c.setSecure(false);
   response.addCookie(c);
}
